South Korea's cybersecurity certification system is under threat following Coupang's unprecedented breach affecting 33.7 million users
- Coupang confirmed a 33.7M-user data breach, South Korea's largest privacy incident, exposing personal info like names, addresses, and partial order histories. - Suspected unauthorized access via overseas servers by a former Chinese employee, who is now under investigation for prolonged data extraction. - Authorities are probing Coupang for potential violations of strict data laws, with fines potentially exceeding the 2025 SK Telecom record of $92 million. - The breach highlights systemic cybersecurity fa
Major Data Breach at Coupang Impacts Nearly All Users
Coupang, the top e-commerce company in South Korea, has experienced a significant data breach that compromised the personal information of 33.7 million users—almost its entire customer base. This event is now considered one of the most severe privacy breaches in the nation's history.
Investigations suggest that the breach began around June 24 and remained undetected for approximately five months. During this period, sensitive data such as customer names, email addresses, phone numbers, delivery locations, and partial order records were exposed. Coupang has stated that no payment information, credit card details, or login credentials were accessed. Nevertheless, the magnitude of the incident has sparked serious concerns about cybersecurity standards and regulatory effectiveness in South Korea’s digital marketplace.
Suspect Identified in International Data Theft
Authorities believe the breach was carried out through unauthorized access from overseas servers. Police have identified a former Chinese employee of Coupang, who has since left both the company and South Korea, as a primary suspect. This case stands out from previous regional data leaks, which were usually the result of external cyberattacks. Coupang’s CEO, Park Dae-joon, has issued a public apology, admitting to shortcomings in internal security and pledging full cooperation with the ongoing investigation.
Government Response and Potential Penalties
In response to the breach, government agencies have launched an urgent inquiry to determine if Coupang failed to comply with South Korea’s strict personal data protection regulations. The Ministry of Science and ICT, along with the Personal Information Protection Commission, is closely examining the company’s practices. This incident surpasses the scale of SK Telecom’s April 2025 data leak, which affected 23.2 million users and resulted in a record fine of 134.8 billion won (about $92 million). Experts predict that Coupang could face even harsher penalties due to the larger number of affected accounts and its history of repeated breaches since 2020.
Ongoing Criticism Over Security Practices
Despite holding the ISMS-P certification—a government-backed security standard—since 2021, Coupang has suffered four separate data breaches and incurred fines totaling 1.5 billion won (approximately $1.02 million) over the past five years. This latest incident has intensified scrutiny of national cybersecurity certifications, with critics arguing that oversight must adapt to counter increasingly sophisticated internal threats.
Wider Implications for South Korea’s Digital Security
The breach highlights growing weaknesses in South Korea’s digital infrastructure. The Korea Internet & Security Agency has issued warnings to affected users about the risks of phishing and identity theft. Coupang has advised customers to stay alert for suspicious messages and to monitor their accounts for any unauthorized activity. The incident has also renewed calls for stronger enforcement of data protection laws, with lawmakers demanding greater corporate accountability.
As investigations proceed, the impact of the breach extends beyond Coupang, underscoring the broader challenges of protecting user data in an increasingly digital society. For South Korea—a global leader in technology and online commerce—this event is a crucial test of its ability to maintain both innovation and robust security measures.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
The transformation of the Xerox campus in Webster, NY: Driving the expansion of industrial real estate in the region
- Webster , NY's former Xerox campus reactivation aims to create a $1B industrial hub by 2026 via $9.8M FAST NY grants and infrastructure upgrades. - Mixed-use zoning enables 500 housing units and 200K sq ft commercial space, blending residential/industrial development to boost workforce retention. - $283M state funding for roads, sewers, and electrical systems transforms the brownfield into a shovel-ready site attracting advanced manufacturing and logistics firms. - Public-private partnerships like the $6

XRP Supply Shock Debate Intensifies as ETF Inflows Drain Exchange Liquidity
Quick Take Summary is AI generated, newsroom reviewed. XRP exchange reserves have fallen by more than 180 million tokens. ETF inflows exceeding $800 million correlate with large withdrawals from Binance and other exchanges. XRP’s outlook depends on long-term ETF demand and Ripple’s escrow distribution pace. OTC and dark-pool liquidity continue to buffer visible market pressure.References X Post Reference
Europe’s Largest Asset Manager Quietly Launches Tokenized Money Market Fund on Ethereum
Quick Take Summary is AI generated, newsroom reviewed. Europe’s largest asset manager Amundi (€2.2T AUM) launched a tokenized euro money market fund on Ethereum. The fund went live without announcement on Nov 4 and was revealed weeks later. The move mirrors institutional adoption trends led by BlackRock and Franklin Templeton. The fund uses Ethereum for 24/7 access, transparency, and global settlement.References X Post Reference
Bitcoin Eyes 2019 Replay as Fed Prepares to End QT on December 1